Who this policy covers
This policy applies to personal data that Bharat IPO ("Bharat IPO", "we", "us", "our") processes as a Data Fiduciary — whether you visit bharatipo.in, submit an enquiry form, speak with an advisor, subscribe to our insights, or engage us on a mandate. It covers website visitors, prospective clients, clients and their authorised representatives, and professional contacts.
Where we process personal data on behalf of a client — for example, director or promoter details supplied to us during due diligence — we act as a Data Processor under that client's instructions and under the confidentiality terms of the engagement letter. In those cases the client's own privacy notice governs the underlying relationship with the individual.
Personal data we collect
We deliberately collect the minimum needed to respond to you and to run a professional engagement. Depending on how you interact with us, that may include:
- Identity and contact data — name, designation, company, email address, telephone or WhatsApp number, and the content of the message you send us.
- Engagement data — correspondence, meeting notes, instructions, scoping information and the documents you or your advisors provide during a mandate.
- Financial and corporate data — company financials, shareholding details, board and promoter information, statutory filings and other records required for IPO readiness, due diligence or valuation work. This may include personal data about your directors, promoters, key managerial personnel and shareholders.
- Verification data — identity and address documentation collected where anti-money-laundering, know-your-client or statutory verification requirements apply.
- Technical data — IP address, browser type and version, device type, referring page, pages visited and time spent, collected through server logs and analytics. See our Cookie Policy for detail.
- Recruitment data — where you apply to us, the CV, qualifications and references you submit.
Sensitive and children's data
We do not seek special-category information such as health, biometric or religious data, and you should not send it to us. Where verification documents incidentally contain such information, we redact or restrict access to it.
Our services are directed at businesses and their advisors. We do not knowingly collect personal data of children under eighteen. If you believe a child's data has been provided to us, write to us and we will delete it.
Why we process your data
We process personal data only where we have a lawful basis to do so — in most cases your consent, the performance of a contract with you, or compliance with a legal obligation. Specifically, we use it to:
- Respond to enquiries, arrange consultations and provide the information you ask for.
- Assess whether we can act — including conflict checks and client acceptance procedures.
- Deliver our services: IPO readiness assessment, DRHP and RHP preparation, due diligence, valuation, restructuring and governance advisory.
- Meet statutory, regulatory and professional obligations, including record-keeping, tax and audit requirements.
- Maintain and secure our systems, prevent fraud, and establish or defend legal claims.
- Send insights, regulatory updates and event invitations where you have asked to receive them. Every such message carries an unsubscribe link.
Confidentiality
Everything a client or prospective client tells us is treated as confidential from the first conversation, whether or not an engagement follows and whether or not a non-disclosure agreement has been signed. Pre-IPO information is price-sensitive by nature and we treat it accordingly.
Access to engagement files is restricted to the team members working on the mandate. Every partner, employee and contractor is bound by written confidentiality undertakings that survive the end of their association with us. We do not use client names or transaction details in marketing without written permission.
Where data is stored
Our systems and records are hosted primarily in India. Some service providers may process limited data — such as email routing or analytics — on servers outside India. Where that happens, we satisfy ourselves that the transfer is permitted under applicable Indian law and that the recipient applies protections comparable to our own.
How long we keep it
We retain personal data only as long as we need it. Enquiries that do not lead to an engagement are deleted within twenty-four months. Engagement records are retained for eight years from the close of the mandate, reflecting statutory limitation periods and professional record-keeping norms, and longer where a regulatory proceeding, dispute or specific legal obligation requires it.
Marketing contact details are kept until you withdraw consent. When a retention period ends, records are securely deleted or anonymised.
Security
We apply access controls on a need-to-know basis, encryption in transit, protected document repositories for engagement files, multi-factor authentication on business accounts, and periodic review of user access. Staff receive confidentiality and data-handling training on joining and at regular intervals.
No system is perfectly secure. If a personal data breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as required under the Digital Personal Data Protection Act, 2023.
Your rights
Subject to the Digital Personal Data Protection Act, 2023 and to our professional and statutory obligations, you may:
- Ask for a summary of the personal data we hold about you and how we process it.
- Ask us to correct data that is inaccurate, or complete data that is incomplete.
- Ask us to erase data we no longer need for the purpose it was collected or for a legal obligation.
- Withdraw consent at any time, with effect going forward, where processing rests on consent.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Complain to the Data Protection Board of India if you are not satisfied with our response.
Exercising your rights
Write to hello@bharatipo.in with enough detail to identify you and the request. We may ask for proof of identity before acting. We respond within thirty days. Where we cannot fully comply — for example because the data forms part of a statutory record or a client's engagement file we do not control — we will tell you why.
Changes to this policy
We review this policy at least annually and update it when our practices or the law change. The effective date at the top of this page always reflects the current version. Material changes will be highlighted on this page for a reasonable period.
How to contact us
Questions, requests or complaints relating to privacy and personal data should be addressed to Bharat IPO at hello@bharatipo.in, or by post to our office in Mumbai, Maharashtra, India. Please mark your communication for the attention of the Grievance Officer and include enough detail for us to identify you and the matter concerned.
We acknowledge every substantive communication within three business days and aim to resolve it within thirty days. Where a matter requires longer — for example because it involves third parties or archived records — we will tell you why and give you a revised timeline.
This page is provided for information and does not itself constitute legal advice. Where a signed engagement letter applies to your relationship with Bharat IPO, that letter prevails over anything stated here.